Privacy Policy
This Privacy Policy explains what personal data Voidworks processes, why we use it and your rights under the GDPR.
Last updated: 31 August 2026What data do we collect?
Name, email address, project requests, account and project data, and necessary technical security data. We do not intentionally request special categories of personal data.
Passwords and verification
Passwords are processed by Supabase Auth and are not stored as readable text in our own database. Voidworks verification codes are stored only as protected hashes and expire automatically.
Why do we process data?
For account administration, handling requests and agreements, communication, support, security, fraud prevention, legal obligations and technical operation of the service.
GDPR legal bases
Depending on the processing, we rely on contract or pre-contractual steps, legitimate interests for security and service delivery, legal obligations, and consent for optional preferences.
Who do we share data with?
We do not sell personal data or share it for advertising. Technical processors such as Supabase, Vercel, Resend, Cloudflare and GitHub may process data for hosting, authentication, email, security and backups.
Retention
We keep data only as long as necessary. Security tokens expire quickly and database backups are deleted after 7 days by default.
Your GDPR rights
You can request access, correction, deletion, restriction, portability or object via info@voidworks.eu. Consent can be withdrawn and you may complain to your data protection authority.
Deleting your account
You can delete your account from the dashboard. This removes the Auth account and linked application data, except data that must temporarily be retained for legal or security reasons.
Security
We use HTTPS/HSTS, access controls, RLS, server-side secrets, rate limits, CSRF and origin checks, Turnstile, limited session duration, security headers and private backups. No system can guarantee absolute security.

